The MIT declaration and lack of install-time scripts reduce immediate adoption friction. Its README says the project is not for production, and the repository has no security policy, so depend on it only with a clear replacement plan.
35%
Total Score
0
100
69
75
The latest release was published in October 2020, with no releases in the last 12 months. Nearly six years without a release is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the nearly six-year release gap and indicating no visible maintenance capacity.
A README is present, but its explicit warning that the project is work in progress and should not be used in production materially limits confidence for dependency adoption. The missing tests and changelog are not treated as packaging gaps.
The repository has zero stars and forks and only two watchers. Low visibility does not prove the package is unsafe, but it provides little supporting evidence of community review or adoption.
The repository has no security policy. This is a transparency and maintenance gap for a package that may handle application address data, although it is not a severe risk by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.